Today many see cyber intelligence as the only possible hope to get ahead and stay ahead of the continuously changing cyber threatscape. Cyber intelligence is relatively new when compared to the practice of intelligence gathering in general. Few people would dispute its rapid rise to the level of critical importance.
With that increased importance has come new tools, techniques and practices. That is why the cyber intelligence market is projected, by some accounts, to grow to nearly $6 billion by 2020. Today most organizations rely on an array of tools, techniques, sources and methods to collect, analyze and leverage cyber intelligence. While most organizations recognize the need to continuously improve their cyber intelligence gathering, analysis, modeling and utilization, some question the real return on investment.
One interesting point became all too apparent. Looking at at least one commonly used framework, there was no validation in the process diagram. One would think given the importance that validation would be a component of sourcing, processing, analysis and discrimination.
I just recently got to experience one of the more significant and related issues when it comes to cyber intelligence. A piece of intelligence was presented, and it drew a sharp response from one individual who had provided a similar, but conflicting, account. Both sources were reputable with similar credentials. No resolution was reached as to which account was accurate. Using open source intelligence, I researched the issue and was able to find support for both accounts.
With all the cyber data, information and intelligence out there it is highly likely that repeats of these types of situations will become much more frequent and possibly the norm. When seeking some way to resolve this issue I recalled the guidance to move away from emotional responses. That hardly sounds scientific, but the only other option is to just wait and see.








